Poker
Online Poker Hit by New ‘Superuser’ Scandal as Malware Exposes Players’ Hole Cards
Posted on: October 5, 2026, 08:14h.
Last updated on: October 5, 2026, 08:14h.
Online poker may have a genuinely nasty new “superuser” scandal on its hands. Several high-stakes online poker players have reported being targeted by a sophisticated cyber-attack that allowed a cheater to secretly view their computer screens—and their hole cards—in real time.

The attacker is believed to have compromised third-party software used by high-volume online players to organize multiple poker tables, install hotkeys, and manage other aspects of their games.
Jurojin Poker, one of the software providers affected, acknowledged this week that an attacker was able to intermittently replace updates sent to a select group of users with tampered versions containing remote-access software.
“This was a highly targeted operation, not a mass attack,” Jurojin said. The company added that the attacker was a “known cheater” targeting specific high-stakes opponents with the aim of viewing their hole cards remotely.
A second popular poker-management program, IntuitiveTables, was also compromised, according to Jurojin and reports on the investigation. Neither company has been accused of knowingly participating in the scheme.
Watching From Inside the Computer
The malware was based on MeshCentral, legitimate remote-management software normally used by IT departments to access computers remotely.
Once installed, however, the hidden “Mesh Agent” could reportedly allow whoever controlled it to watch an infected player’s screen and operate the computer remotely. In an online poker game, that would provide an enormous advantage: the attacker could see an opponent’s face-down cards while the hand was being played.
Cybersecurity researcher “WolfSec0x0,” who first exposed the operation on X, initially identified between 10 and 30 affected computers across Europe, North America, and Oceania.
Jurojin said its own compromised updates were delivered intermittently between June 2025 and January 2026 and that only a small group of users was targeted. The company has contacted potentially affected customers and provided information to law enforcement and poker-site security teams.
‘Superuser’ Suspicions
The discovery adds weight to suspicions some high-stakes players have recently voiced about certain accounts they believed were producing implausibly strong results.
PokerNews reported that an account using the name “Paul Gregg” had been flagged by players before the malware operation became public. Poker coach Patrick Howard reportedly sent GGPoker an analysis in September highlighting unusual results and asking the company to investigate, although he stopped short of accusing the player of cheating.
Meanwhile, CoinPoker ambassador Patrick Leonard said the site had previously banned an account called “Europe,” which he said was registered in Paul Gregg’s name, confiscating more than $100,000 and reimbursing affected players.
High-stakes player Ignacio Morón has claimed he lost between $100,000 and $200,000 playing against the suspect account, including about $60,000 during one 15-minute session.
The revelations have already prompted at least one poker operator to change its software. ACR Poker said it has developed a “Screen Shield” designed to prevent its tables from being visible to screen-capture and screen-sharing programs.
Potripper and “God Mode”
The incident recalls the notorious superuser scandals of the 2000s. In 2007, an account called “Potripper” was exposed by players on the TwoPlusTwo forums after producing implausibly successful results on Absolute Poker.
Absolute Poker later acknowledged that seven accounts had been used to cheat players over a 40-day period and promised $1.6 million in refunds.
Investigators determined that insiders had access to software capable of revealing opponents’ hole cards in real time — a capability players dubbed “God Mode.” The Potripper account was subsequently widely linked to a former Absolute Poker director of operations, although regulators never publicly identified its operator.
A similar and much larger scandal emerged at Absolute Poker’s sister site, UltimateBet. Investigators identified former WSOP Main Event champion and UltimateBet consultant Russ Hamilton as the primary offender in a scheme that likewise exploited access to opponents’ hidden cards.
Conversation (0)
Be the first to comment on this article.